Use authorised identities and tenant boundaries. Return only the data needed for the account task. Do not expose private communication records merely because an executive name appears in a query.
Distinguish research, internal request creation, connector approval and external sending. A graph result should not silently trigger a message on someone else's behalf.
External research can contain incorrect information or instructions that should not control the agent. Treat it as evidence to assess, not authority to change sending or access rules.
Check former employees, disconnected sources, changed roles and denied access. Confirm that logs capture meaningful actions without creating an unnecessary copy of sensitive data.
This is an architectural evaluation framework. For Orbb, use current documentation and the agreed deployment to confirm supported access controls and approval flows. Do not assume a particular API permission model until it has been demonstrated.